Connect Microsoft Entra ID (formerly Azure Active Directory) to SurrealDB to allow members of your organisation to sign in with their Microsoft accounts. You register an application in the Microsoft Entra admin center, then enter its details in a new connection in SurrealDB Studio.
Before you start, verify the email domain your company uses. You also need an Entra account that can register applications.
Step 1: Register an application
In the Microsoft Entra admin center, open Entra ID, then App registrations.
Select New registration.

Enter a Name, for example
SurrealDB.Under Supported account types, select Single tenant only, so that only accounts in your directory can sign in.
Under Redirect URI, select Web as the platform and enter
https://auth.surrealdb.com/login/callback.Select Register.

Step 2: Copy the application ID
Entra opens the Overview of the new application. Copy the Application (client) ID.

Step 3: Check the API permissions
Open API permissions and make sure the application has the delegated Microsoft Graph permission User.Read. A new registration usually has it already. If it is missing, select Add a permission, then Microsoft Graph, then Delegated permissions, and add User.Read.
Step 4: Create a client secret
Open Certificates & secrets.
On the Client secrets tab, select New client secret.
Enter a Description, for example
SurrealDB, and choose when it Expires.Select Add.

Copy the secret's Value, not its Secret ID. Entra shows the value only once, while you are still on the page.
Sign-in through this connection stops working on the date the client secret expires. Note the date, and create a new secret and update the connection in SurrealDB before then.
Step 5: Add the connection in SurrealDB
Open Single sign-on in your enterprise and add a new connection.
Select Microsoft Entra ID.
Under Name the connection, enter a Display name. Members see this name on the sign-in screen.
Under Enter the Microsoft Entra ID details, enter:
Directory domain: a domain of your directory, for example
example.onmicrosoft.com.Client ID: the application (client) ID from step 2.
Client secret: the secret value from step 4.
Under Route sign-in domains, select the verified domains to send to this connection. This is optional, and you can change it later.
Select Create connection.
The Set up Microsoft Entra ID section of the form shows the redirect URI, with a copy button beside it, if you need it again.

SurrealDB stores the client secret securely and does not show it again.
Next steps
If you did not route a domain when you created the connection, route one now. Then choose the applications that people can sign in to with this connection.